Security brief: tax scams aim to steal funds from taxpayers

March 30, 2026, 10:12 a.m.

Description

Threat actors are exploiting tax season with numerous campaigns leveraging tax themes to deliver malware, remote monitoring tools, fraud attempts, and credential phishing. Over a hundred campaigns have been observed in 2026, with a notable increase in remote monitoring and management (RMM) payloads. Tactics include impersonating tax agencies, claiming expired documents, and requesting tax filing support. While primarily targeting the United States, campaigns have also been observed in Canada, Australia, Switzerland, and Japan. Notable actors include TA4922, a newly designated threat group delivering malware from the Winos4.0 ecosystem, and TA2730, focusing on credential phishing for financial institutions. Business email compromise actors are also using tax form lures to steal financial and personal data. These campaigns demonstrate the ongoing exploitation of timely and topical themes by cybercriminals to deceive users.

Date

  • Created: March 30, 2026, 9:16 a.m.
  • Published: March 30, 2026, 9:16 a.m.
  • Modified: March 30, 2026, 10:12 a.m.

Indicators

  • d338a7f85737cac1a7b4b5a1cca94e33d0aa8260548667c6733225d4c20cb848
  • 844202972ff19afa760447fc87963de0fbbc0ebc69d50164f03ecf5d4e67952f
  • 121.127.232.253
  • www.upsystems.one
  • https://www.upsystems.one/Alex.exe

Attack Patterns

Additional Informations

  • Finance
  • iuzndfqr.com
  • gyglowcq.com
  • akcjdrya.com
  • rmwztbrr.com
  • whghfpytehu.com
  • wijgzsfh.com
  • bksgcefzqyb.com
  • nirbsff.com
  • buwxkiy.com
  • eodrggi.com